Project

General

Profile

Actions

Feature #16623

open

Account Key fields for External Account Binding

Added by Jim Pingle 7 days ago.

Status:
New
Priority:
Normal
Assignee:
Category:
ACME
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:

Description

Some CAs now use External Account Binding instead of typical Account Key registration, including:

  • ZeroSSL
  • SSL.com
  • Google
  • Actalis
  • StepCA (optional, depends on the server config)

This requires two fields:

"EAB Key ID" and "EAB HMAC Key"

These fields are used when registering the account initially via acme.sh, e.g.

acme.sh --register-account \
        --server <name> \
        --eab-kid <id> \
        --eab-hmac-key <hmac>

They are not necessary for Let's Encrypt so should be hidden by default unless using one of the other CAs or a custom CA. If using a custom CA, they should only be passed if the user filled them in.

No data to display

Actions

Also available in: Atom PDF